Global Privacy Policy
Effective Date: 08 July 2026 · Version 2026-07-08
Kayana for Business Limited, and any and/or other related entities under the Kayana for Business company structure (including Kayana World Limited, Kayana Ireland Limited, Kayana for Business Australia LLC, and Kayana for Business Canada) (collectively, "Kayana", "we", "us" or "our"), is committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, store, transfer, disclose and otherwise process personal data when you access or use Kayana Aid ("Platform"), including when you make donations, create an account, register a cause, participate in fundraising activities or otherwise interact with us.
This Privacy Policy is intended to comply with applicable privacy and data protection laws, including where relevant:
- UK General Data Protection Regulation ("UK GDPR")
- Data Protection Act 2018
- EU General Data Protection Regulation ("EU GDPR")
- The California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable US state privacy laws (e.g. Virginia, Colorado, Connecticut, Utah)
- UAE data protection laws, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
- Saudi Arabia's Personal Data Protection Law ("PDPL") and its implementing regulations
- Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act ("PIPEDA") and, where applicable, Quebec's Act Respecting the Protection of Personal Information in the Private Sector ("Law 25")
- Australian privacy legislation, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles
1. Who We Are
Kayana for Business Limited is the operator of Kayana Aid and acts as the data controller for personal data collected through the Platform unless otherwise stated.
Contact Details
Company: Kayana for Business Limited
Registered Office: Office No 211, Al Hudaiba Mall, 2nd Floor, Dubai, UAE
Email: info@kayanaforbusiness.com
Website: www.kayanaforbusiness.com
We have a Data Protection Officer that can be contacted for UK, EU, UAE, Australia, Canada and all other jurisdiction data privacy queries, concerns or questions via: compliance@kayana.co.uk
UK/EU Representative – Sarfraaz Patel
2. Information We or the PSP May Collect
We or our payment service providers ("PSPs") (currently Stripe, Ryft, Mollie and Nuvei) may collect and process the following categories of personal data. We generally do not store any personal documentation of any customer/merchant. Documents collected will be stored by the PSP.
Identity Information
- Full name
- Date of birth
- Nationality
- Government-issued identification documents
- Photographs
- Verification information
Contact Information
- Email address
- Telephone number
- Postal address
- Country of residence
Donation Information
- Donation amounts
- Donation history
- Campaign information
- Transaction references
- Gift Aid declarations (where applicable)
- Donation preferences
Cause and Merchant Information
- Organisation details
- Registration information
- Beneficial ownership information
- Trustee or director information
- Compliance documentation
Financial Information
We generally do not store complete payment card details.
Payment information may be collected and processed by authorised PSPs and financial institutions. We may receive:
- Payment confirmations
- Transaction references
- Settlement information
- Limited payment metadata
Technical Information
- IP address
- Browser type
- Device information
- Operating system
- Session data
- Device identifiers
- Cookies and similar technologies
Compliance Information
- AML screening results
- Sanctions screening results
- Fraud monitoring information
- Risk assessments
- Regulatory compliance information
3. How We Collect Information
We collect information:
- Directly from you
- Through forms and registrations
- During donation transactions
- Through communications with us
- Through cookies and analytics technologies
- From PSPs and financial institutions
- From verification providers
- From public records and compliance databases
- From regulatory and law enforcement bodies where legally permitted
4. Purposes of Processing
We process personal data for the following purposes:
Platform Administration
- Creating and managing accounts
- Operating the Platform
- Providing customer support
Donations and Fundraising
- Processing donations
- Managing fundraising campaigns
- Supporting donor communications
Compliance
- Conducting KYC and KYB checks
- Conducting sanctions screening
- Conducting anti-money laundering checks
- Preventing financial crime
- Meeting regulatory obligations
Security
- Detecting fraud
- Monitoring suspicious activity
- Protecting Platform integrity
- Preventing unauthorised access
Business Operations
- Analytics
- Research
- Service improvement
- Reporting
- Auditing
Marketing and Communications
Where legally permitted:
- Sending updates
- Providing service notifications
- Sharing fundraising updates
- Marketing related services
5. Legal Basis for Processing
Where UK GDPR, EU GDPR or similar laws apply, processing may be based upon:
Contractual Necessity
Where processing is required to provide the Platform.
Legal Obligations
Where processing is necessary to comply with applicable laws and regulations.
Legitimate Interests
Including:
- fraud prevention
- security monitoring
- service improvement
- business administration
- regulatory compliance
Consent
Where consent is required by law. You may withdraw consent at any time.
Purpose-to-Basis Summary
The table below summarises the primary lawful basis relied on for each main purpose. Where more than one basis could apply, we rely on the most appropriate basis in the circumstances.
Purpose-to-Basis Summary
| Purpose | Primary Legal Basis |
|---|---|
| Account creation and Platform operation | Contractual necessity |
| Processing donations and payments | Contractual necessity |
| KYC / KYB / sanctions / AML screening | Legal obligation; substantial public interest (Art. 9, for ID/biometric data) |
| Fraud detection and security monitoring | Legitimate interests / legal obligation |
| Analytics and service improvement | Legitimate interests |
| Marketing communications | Consent (or soft opt-in where permitted) |
| Gift Aid claims | Legal obligation / consent (declaration) |
6A. Special Category and Biometric Data
As part of identity verification, we or our verification providers may process government-issued identification documents and photographs, which may constitute special category data (including biometric data used for the purpose of uniquely identifying an individual) under Article 9 of the UK GDPR/EU GDPR.
Where we process this data, we do so on the basis of:
- your explicit consent; and/or
- the substantial public interest condition relating to the prevention or detection of unlawful acts, fraud, and compliance with anti-money laundering and counter-terrorist financing obligations,
as permitted under applicable law and subject to appropriate safeguards. Where we rely on the substantial public interest condition, we maintain an internal Appropriate Policy Document setting out our compliance measures and retention approach for this data, in accordance with the UK Data Protection Act 2018.
6. Sanctions, AML and Fraud Prevention
Kayana may process personal data for:
- sanctions screening
- anti-money laundering controls
- fraud detection
- counter-terrorist financing controls
- risk assessments
- regulatory investigations
Where required, information may be disclosed to regulators, law enforcement agencies, PSPs, financial institutions and governmental authorities.
7. Disclosure of Information
We may disclose personal data, if and when needed, to:
Service Providers
- PSPs
- Banks
- Verification providers
- Cloud providers
- Analytics providers
- Security providers
- Customer support providers
Regulators and Authorities
- Law enforcement agencies
- Regulatory authorities
- Courts and tribunals
- Government agencies
Corporate Transactions
In connection with:
- mergers
- acquisitions
- restructurings
- investments
- financing transactions
We do not sell personal data.
We do not share personal data for cross-context behavioural advertising as defined under the CCPA/CPRA. If this changes, we will update this Policy and provide a mechanism to opt out.
Causes, Charities and Merchants
Where you donate to a specific cause, charity, or merchant registered on the Platform, we may share relevant donor information (such as your name, contact details, and donation amount) with that organisation so it can acknowledge your donation, issue receipts, or claim Gift Aid. Each cause, charity, or merchant acts as an independent data controller for the personal data it receives in this way, and its own privacy policy will govern its use of your data. We are not responsible for how a cause, charity, or merchant uses your data once it has been lawfully disclosed to them.
8. International Transfers
Personal data may be transferred to, processed in or accessed from:
- United Kingdom
- European Economic Area
- United States
- United Arab Emirates
- Saudi Arabia
- Canada
- Australia
- Other jurisdictions where our providers operate
Where personal data is transferred from the UK or EEA to a country that does not benefit from an adequacy decision (including the United Arab Emirates, Saudi Arabia, and the United States, save for participants in an approved framework), we implement appropriate safeguards, which may include:
- the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses
- the EU Standard Contractual Clauses
- reliance on an approved certification framework (e.g. the EU-US Data Privacy Framework), where the recipient participates; or
- other lawful transfer mechanisms recognised under applicable law
You may request further information about the safeguards we have put in place by contacting us using the details in Section 17.
9. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes it was collected, applying the following general retention periods:
Retention Periods
| Category of data | Typical retention period |
|---|---|
| Account and profile information | Duration of account, plus 2 years following closure |
| Donation and transaction records | 6 years from the transaction (statutory/tax record-keeping) |
| KYC / KYB / identity verification documents | As instructed by, and typically held by, the PSP/verification provider; we retain screening results for up to 10 years where required by AML law |
| Gift Aid declarations | As required by HMRC guidance (currently up to 6 years after the last claim, or longer for a running declaration) |
| Cookies and technical/analytics data | See Section 11 and our cookie table; typically 13 months or less |
| Marketing preferences and consent records | Until consent is withdrawn, plus a record of the withdrawal |
| Complaints, disputes and regulatory correspondence | Duration of the matter plus 6 years |
9B. Retention — General Note
Retention periods may be extended where necessary for legal obligations, anti-money laundering requirements, fraud prevention, tax compliance, dispute resolution, or regulatory investigations. Certain compliance records may be retained for up to ten (10) years or longer where required by law.
10. Security
We maintain reasonable technical and organisational safeguards designed to protect personal data. Measures may include:
- encryption
- access controls
- monitoring systems
- authentication procedures
- security testing
However, no system can guarantee absolute security.
10A. Data Breach Notification
If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will, where required by applicable law:
- notify the relevant supervisory authority (such as the ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach; and
- notify you directly, without undue delay, where the breach is likely to result in a high risk to your rights and freedoms
Any notification to you will describe the nature of the breach, the likely consequences, and the measures taken or proposed to address it and mitigate its effects.
11. Cookies and Similar Technologies
What Are Cookies?
Cookies are small text files placed on your device when you visit or use the Platform. We may also use:
- pixels
- web beacons
- local storage technologies
- SDKs
- device identifiers
- similar tracking technologies
Types of Cookies We Use
Strictly Necessary Cookies
These cookies are essential to operate the Platform. Examples include:
- user authentication
- security monitoring
- donation processing
- fraud prevention
- session management
These cookies cannot be disabled through our systems.
Functional Cookies
These cookies allow us to remember preferences and improve usability. Examples include:
- language settings
- accessibility preferences
- regional settings
Analytics Cookies
These cookies help us understand how users interact with the Platform. Examples include:
- page visits
- session duration
- traffic patterns
- user behaviour statistics
Analytics data may be aggregated and anonymised.
Marketing Cookies
Where legally permitted, marketing cookies may be used to:
- measure campaign effectiveness
- improve communications
- analyse advertising performance
Third-Party Cookies
Third parties may place cookies through the Platform, including:
- PSPs
- analytics providers
- cloud providers
- security providers
- communications providers
Their use is governed by their own privacy policies.
Cookie Consent
Where required by law, we will seek consent before placing non-essential cookies. You may:
- accept cookies
- reject cookies
- withdraw consent
- modify cookie preferences
Strictly Necessary Cookies remain active as they are required for Platform operation.
Managing Cookies
Most browsers allow you to:
- block cookies
- delete cookies
- receive cookie notifications
- control cookie settings
Disabling cookies may impact Platform functionality.
Security and Fraud Monitoring
Kayana may use cookies and device technologies to:
- detect fraud
- authenticate users
- prevent account compromise
- support AML controls
- protect Platform security
11A. Marketing Communications
Where we send electronic marketing (such as email or SMS) to individuals, we comply with the UK Privacy and Electronic Communications Regulations ("PECR") and equivalent laws in other jurisdictions where applicable. This means we will:
- only send marketing by email or SMS with your consent, or in reliance on the "soft opt-in" for existing donors/customers regarding similar services, where permitted
- include an unsubscribe/opt-out mechanism in every marketing communication; and
- stop sending marketing communications promptly once you opt out, while continuing to send transactional/service communications necessary to operate your account
12. Your Rights
Subject to applicable law, you may have the right to:
- access personal data
- correct inaccurate data
- erase personal data
- restrict processing
- object to processing
- request portability
- withdraw consent
Requests may be submitted to: info@kayanaforbusiness.com
We will respond to your request within one month of receipt. This period may be extended by a further two months where the request is complex or we have received a number of requests from you, in which case we will let you know within one month and explain why the extension is necessary.
We may require identity verification before responding.
Additional Rights for US Residents
If you are a resident of a US state with an applicable privacy law (such as California), you may also have the right to:
- opt out of the sale or sharing of your personal information (we do not currently sell or share personal information as described in Section 7)
- limit the use of sensitive personal information; and
- not be discriminated against for exercising your privacy rights
13. Children
The Platform is not intended for persons under 18 years of age.
We do not knowingly collect personal data from children without appropriate legal authority.
Where a fundraising campaign is run by or on behalf of a minor (for example, a school or youth group fundraiser), we require that the campaign be registered and supervised by a parent, guardian, teacher, or other responsible adult, who will act as the account holder and point of contact for that campaign. If we become aware that we have collected personal data directly from a child without appropriate consent or legal authority, we will take reasonable steps to delete that information promptly.
14. Automated Decision-Making
Kayana may use automated systems for:
- fraud detection
- sanctions screening
- compliance assessments
- risk monitoring
Such processing may contribute to decisions regarding Platform access or transaction approval.
Where such processing results in a decision based solely on automated means that produces a legal effect or similarly significantly affects you (for example, a blocked transaction or a suspended account), you have the right to:
- obtain human intervention and request that a person reviews the decision
- express your point of view; and
- contest the decision
To exercise these rights, contact us using the details in Section 17. We will not use automated decision-making that produces such effects based on special category data unless a further condition under Article 9 and Article 22(4) GDPR is met.
14A. Gift Aid and HMRC Disclosure
If you make a Gift Aid declaration, we will share the information contained in that declaration — including your name, home address, and donation details — with HM Revenue & Customs ("HMRC") for the purpose of enabling the relevant charity or cause to claim Gift Aid tax relief on your donation. This information may also be shared with the charity or cause you are supporting so that it can submit and substantiate the claim. We retain Gift Aid declarations and supporting records for the period required by HMRC guidance.
15. Changes to this Policy
We may amend this Privacy Policy from time to time. Updated versions will be published on the Platform.
Where changes are material — for example, a change that affects your rights or how we use your personal data — we will take reasonable steps to notify you directly (such as by email or an in-app notice) in addition to publishing the updated Policy.
Continued use of the Platform following publication constitutes acknowledgement of the updated Policy.
16. Complaints
If you have concerns regarding our processing of personal data, please contact us first.
Where applicable, you may also lodge a complaint with the relevant supervisory authority, including:
- the Information Commissioner's Office ("ICO") in the United Kingdom (ico.org.uk)
- the relevant supervisory authority in your EEA member state, if applicable
- the UAE Data Office, for complaints relating to processing in the UAE
- the Saudi Data & Artificial Intelligence Authority ("SDAIA"), for complaints relating to processing in Saudi Arabia
- the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information for Quebec residents; and
- the Office of the Australian Information Commissioner ("OAIC"), for Australian residents
17. Contact Us
Kayana for Business Limited
Registered Office: Office No 211, Al Hudaiba Mall, 2nd Floor, Dubai, UAE
Email: info@kayanaforbusiness.com
Website: www.kayanaforbusiness.com
